Several vulnerabilities were discovered in Libvirt, a virtualisation
abstraction library:

CVE-2018-1064

Denial Berrange discovered that the QEMU guest agent performed
insufficient validationof incoming data, which allows a privileged
user in the guest to exhaust resources on the virtualisation host,
resulting in denial of service.

CVE-2018-5748

Daniel Berrange and Peter Krempa that the QEMU monitor was suspectible
to denial of service by memory exhaustion. This was already fixed in
Debian stretch and only affects Debian jessie.